CVE-2024-25864: SSRF
Published Apr 3, 2024
·Updated
Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.
Affected Software
1 affected component
Friendica Friendica>2023.12
Event History
Apr 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25864?
CVE-2024-25864 is considered to have a high severity due to its potential for remote code execution and data exposure.
2
How do I fix CVE-2024-25864?
To fix CVE-2024-25864, upgrade to Friendica version 2023.12 or later, where the vulnerability has been addressed.
3
What kind of attacks can be performed using CVE-2024-25864?
CVE-2024-25864 allows attackers to execute arbitrary code and access sensitive information through Server Side Request Forgery (SSRF) techniques.
4
On which versions of Friendica is CVE-2024-25864 present?
CVE-2024-25864 affects Friendica versions released after 2023.12.
5
What component is exploited in CVE-2024-25864?
The vulnerability CVE-2024-25864 is exploited through the fpostit.php component of Friendica.